MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, many pointing to potentially malicious domains, suggesting a link farm or SEO poisoning tactic. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic strongly indicate an attempt to redirect users to harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/aws?utm_term=the+man+in+the+high+castle+netflix+espa%25C3%25B1a
- https://cdn.sqhk.co/lupobikud/d3gf6if/mix_wall_paint_with_water.pdf
- https://disovipogazita.weebly.com/uploads/1/3/1/3/131398104/jepopirawaw.pdf
- https://cdn.sqhk.co/nifodotiriru/ajgyheR/crush_hits_me.pdf
- https://tomosuboma.weebly.com/uploads/1/3/5/3/135382902/kavegebamaku.pdf
- https://cdn.sqhk.co/nekuripafi/jifXDpQ/my_airtel_number_offer.pdf
- http://gokutep.22web.org/43540836355.pdf
- http://jibuwuxopi.22web.org/goggle_lens_color_guide_motocross.pdf
- https://cdn.sqhk.co/vobilurerire/iV4ibY2/nevuroronisaxalugo.pdf
- https://bewulikafujisew.weebly.com/uploads/1/3/5/3/135326730/6199925.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/luxelula/cic_employer_portal_user_guide.pdf
- https://uploads.strikinglycdn.com/files/a17465c4-63e4-4036-9b1d-2f41eb8ac87f/46398769084.pdf
- https://s3.amazonaws.com/jebokizez/progress_report_comments_ontario.pdf
- https://uploads.strikinglycdn.com/files/64671ce1-333b-45c2-909c-e90d56da9679/telugu_bible_commentary_free_download.pdf
- https://s3.amazonaws.com/wekibik/riradobudenimo.pdf
- https://uploads.strikinglycdn.com/files/9253c508-4005-4f48-8d14-b2f9a81c9777/fegijure.pdf
- http://notufexunu.rf.gd/dubai_metro_stations_map.pdf
- https://uploads.strikinglycdn.com/files/c024e408-5cde-49a8-89b8-069c27da4039/jopeminaponunevudimideg.pdf
- https://uploads.strikinglycdn.com/files/c560cacc-a3d8-4e97-abae-94431646e926/heart_of_darkness_important_quotes_explained.pdf
- https://uploads.strikinglycdn.com/files/3eef61e6-723c-4b47-80d2-b311553904b5/how_to_train_your_dragon_3_characters_wiki.pdf
- https://uploads.strikinglycdn.com/files/59c18b65-88b9-46dd-bac8-4611c0c3e216/progressive_tense_exercises_with_answers.pdf
- https://s3.amazonaws.com/moduluzuxikari/is_a_kindle_oasis_worth_it.pdf
- https://s3.amazonaws.com/suxuzubojut/1407043144.pdf
- https://uploads.strikinglycdn.com/files/ac859481-6047-4021-b0a3-855705b84700/saxojetasudorirazatonu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f57a.bin9981dca18bee4c890016958766f3ef7915c74b35ea8fd73e603788652010ab96 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF57A | 5560 bytes |
font_01_sfnt_off0001080c.bin698461a6a10fca87a57d69782c65dfd11d117720572cd54e24a753f526510e00 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1080C | 11316 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.